Document Access Control via User Relationship Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In online conferences, sharing documents with all attendees raises information security concerns, as unrestricted access allows all users to manipulate documents, leading to potential misuse and security issues.
Innovation Solution
A document-usage control apparatus that registers relationship information between users and controls document access based on these relationships, allowing or restricting access based on direct or indirect connections to the organizer, thereby defining a sharing range separate from the attendance range.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a document is disclosed across the board to all users who attend an online conference, then the ease of operation is improved, but information security deteriorates
Solution Approach 1:
The patent segments the user group into different categories based on their relationship to the organizer (e.g., direct subordinates, indirect subordinates, external users). Document sharing permissions are then assigned to each segment independently, allowing the organizer to control which segments can access the document. This resolves the contradiction by maintaining ease of operation for authorized segments while preventing unauthorized access to protect information security.
Solution Approach 2:
The patent applies different access control policies to different user segments rather than applying a uniform policy to all users. Each segment receives appropriate document access rights based on their specific relationship to the organizer and the sensitivity requirements of the document. This allows easy access for trusted segments while maintaining security for sensitive documents, resolving the contradiction between ease of operation and information security.
2Ease of operation
If all users across the board are allowed to manipulate a document, then the ease of operation is improved, but information security deteriorates
Solution Approach 1:
The patent segments manipulation permissions by user segment and document type. Different segments (e.g., direct subordinates vs. external users) are granted different levels of manipulation rights based on their relationship to the organizer. This allows easy manipulation for authorized segments while preventing unauthorized manipulation to protect information security.
Solution Approach 2:
The patent applies differentiated manipulation permissions to different user segments rather than uniform access. Each segment receives manipulation rights appropriate to their trust level and the document's sensitivity requirements, enabling easy operation for trusted users while maintaining security controls for sensitive documents.
3Reliability
If document access is restricted based on user relationships, then information security is improved, but device complexity increases
Solution Approach 1:
The patent introduces an intermediary relationship information database that stores pre-defined relationship data between users and organizers. This intermediary structure simplifies the access control logic by providing a ready-reference source for determining user segments, reducing the complexity of real-time relationship analysis while maintaining security-based access control.
Solution Approach 2:
The patent performs preliminary classification of users into segments based on their relationships with the organizer before document access decisions are made. Relationship information is pre-processed and stored, allowing the system to quickly determine appropriate access rights without complex real-time calculations, thus improving security while minimizing added complexity.
Data Source
AI summary
A document-usage control apparatus includes a memory in which a piece of relationship information is registered for each pair of users, the piece of relationship information indicating a relationship between the pair of users, and a processor configured to control use of a document to be shared at an online conference for each user attending the online conference, the use being controlled based on one or more pieces of relationship information registered in the memory.


